This policy explains how Rouhee Group Ltd, Business ID 2684686-4, Finland (“BehindGate”, “we”) processes personal data as a controller. It covers visitors to behindgate.com, people who create or administer a BehindGate account, and people who contact us.
For the people who view a customer’s Apps (“Viewers”), the customer is the controller and we process personal data on the customer’s behalf under the Data Processing Agreement. Section 7 explains what that means for Viewers.
1. Controller and contact
Controller: Rouhee Group Ltd, Business ID 2684686-4, registered in Finland. Data protection contact: legal@behindgate.com.
2. Website visitors
When you visit behindgate.com we process:
- technical request data such as IP address, user agent, requested page, and timestamp, held in edge and web server logs for security and troubleshooting;
- aggregated analytics collected by Plausible Analytics, which uses no cookies, stores no persistent identifier, and does not track you across sites.
Legal basis: our legitimate interest in operating a secure website and understanding how it is used (Article 6(1)(f) GDPR). Log data is kept for up to 90 days. Analytics data is aggregated and does not identify you.
The marketing website sets no cookies and shows no cookie banner because none is needed.
3. Account holders and administrators
When you create an account, invite members, or administer a tenant we process:
- identity and contact data: name, work email address, organisation name, and the authentication identifiers issued by our identity service;
- billing data: plan, invoices, VAT number, and the payment status provided by our payment processor. We do not store full payment card numbers; they are held by Stripe;
- configuration data: sites, domains, viewer authentication configuration (identity provider settings, or the allowed email domains and allowed email addresses for email one-time codes), deploy tokens, and members;
- usage and audit data: sign-ins, actions taken in the dashboard and API, IP addresses, and timestamps, kept for security and to give you audit logs;
- communications: support requests and notices sent to you.
Legal bases: performance of the contract with the organisation you represent (Article 6(1)(b)), our legal obligations such as accounting rules (Article 6(1)(c)), and our legitimate interest in securing the Service, preventing abuse, and improving it (Article 6(1)(f)).
We send service notices, such as changes to terms, security alerts, and billing messages, to account administrators. These are part of the Service and cannot be opted out of while the account is active. Marketing email is sent only with your consent and every message contains an unsubscribe link.
4. Retention
- Account and configuration data: for the life of the account, then deleted within 30 days of termination and from backups within 90 days.
- Audit logs: the retention period of your plan, then deleted.
- Billing records: as long as Finnish accounting law requires, currently six years from the end of the financial year.
- Support communications: up to two years after the case is closed.
- Web server logs: up to 90 days.
5. Recipients
We share personal data with:
- processors that handle personal data we process on a customer’s behalf, listed in the Sub-processor List;
- Stripe Payments Europe, Ltd., which handles subscription billing, invoicing, and payment processing for us. It processes in the European Union, with support from its United States affiliates. Transfers to the United States rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses;
- PostHog, Inc. (PostHog EU Cloud), which provides product analytics for the dashboard so we can see how administrators use it. It processes in the European Union (Frankfurt, Germany);
- our accountants and legal advisers, under confidentiality, and authorities where the law requires.
We do not sell personal data.
6. International transfers
Our infrastructure is hosted by Amazon Web Services in the European Union (Ireland). Some components of the content delivery network, including edge locations and the services that must run in the United States for technical reasons, process request data outside the EU. Such transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses.
7. Viewers of customer Apps
The customer chooses how Viewers sign in to each App: through the customer’s own identity provider (Microsoft Entra ID, Google Workspace, or another OIDC provider), or through an email one-time code (“email OTP”). In both cases the customer configures who is allowed in. We do not maintain a directory of a customer’s Viewers.
When you sign in through the customer’s identity provider, we process on the customer’s behalf the identifier and claims that provider sends, such as your subject identifier, email address, name, and group membership, together with your IP address.
When you sign in with email OTP, the customer’s access configuration (allowed email domains, individual allowed email addresses, or both) determines whether you are eligible. We process the email address you provide to send and verify the one-time code, to authenticate you, and to establish your authenticated session.
In both cases we keep you signed in with a session cookie that is strictly necessary for that purpose, is used for nothing else, and does not track you across sites.
The customer who published the App is the controller and decides who may access it. Contact the customer for questions about that processing or to exercise your rights. We assist customers with such requests as their processor.
8. Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict or object to processing, and to receive data you provided in a portable format. Where processing is based on consent, you may withdraw it at any time. Contact legal@behindgate.com to exercise these rights. We may ask you to verify your identity.
You may also lodge a complaint with the supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
9. Security
We protect personal data with encryption in transit and at rest, access controls, logging, and a fail-closed design for content access. The measures we maintain for customer data are described in the Data Processing Agreement.
10. Changes
We may update this policy. The version and effective date are shown at the top. Material changes are announced by email to account administrators at least 30 days before they take effect.